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About This Guide 


This guide includes information about understanding, setting up, and managing the Remote Console 
utilitv (RConsolej). 


RConsolej lets vou use a network workstation to control and manage a remote NetWare® server. 
You can lock servers in a safe place, remove keyboards and monitors, and then start a remote control 
session from a workstation whenever vou need to access a server's console. 

+ “Overview” on page 9 

+ “What's New” on page 11 

+ “Migrating RConsoleJ from NetWare 6.5 to OES 2 Linux” on page 13 

+ “Running RConsolej in a Virtualized Environment” on page 15 

+ “Setting Up RConsoleJ” on page 17 

+ “Managing NetWare Servers Remotely” on page 25 


+ “Security Considerations for RConsoleJ” on page 27 


Audience 


This guide is intended for network administrators. 


Feedback 


We want to hear your comments and suggestions about this manual and the other documentation 
included with this product. Please use the User Comments feature at the bottom of each page of the 
online documentation, or go to www.novell.com/documentation/feedback.html and enter your 
comments there. 


Documentation Updates 


For the most recent version of the NW 6.5 SP8: Remote Server Management Administration Guide, 
see the NetWare 6.5 SP8 Documentation Web site (http://www.novell.com/documentation/nw65). 


Documentation Conventions 


In Novell® documentation, a greater-than symbol (>) is used to separate actions within a step and 
items in a cross-reference path. 


A trademark symbol e TM. etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party 
trademark. 
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Overview 


NetWare® 6.5 provides Java*-based remote console utility (RConsoleJ) that lets you control a 
NetWare server from a workstation and perform the following tasks: 

+ Use console commands as you would at the server console 

+ Use NLM™ programs as you would at the server console (for example, edit .nim to edit files) 


+ Send console commands in the server’s native language from the RConsoleJ Client using 
Buffer Input. 


¢ Control the server from another server using RConsoleJ 
+ Upgrade a NetWare server (text-based UI only) 


+ Use Secure Socket Layer (SSL) based secure session 


1.1 RConsoleJ Components 


Before setting up RConsoleJ, you should understand the RConsoleJ components. The following 
RConsoleJ components interact with each other to help you remotely control a NetWare server: 


+ “RConsoleJ Client” on page 9 
+ “RConsoleJ Agent” on page 9 
+ “RConsoleJ Proxy Agent” on page 9 


1.1.1 RConsoleJ Client 


The RConsoleJ Client is a Java-based utility running on a Java-enabled workstation or NetWare 
server. From the RConsoleJ Client you can remotely control and monitor all NetWare console 
operations. 


1.1.2 RConsoleJ Agent 


The RConsoleJ Agent (rconag6 .n1m) is a utility running on the target NetWare server. The target 
NetWare server can be connected over IP, IPX™, or IP/IPX running the RConsoleJ Agent. The 
RConsoleJ Agent services all RConsoleJ Client requests. 


The RConsoleJ Agent advertises its services using Service Location Protocol (SLP) on NetWare 5.x 


and later. 


1.1.3 RConsoleJ Proxy Agent 


The RConsoleJ Proxy Agent (rconprxy.nlm) is a utility running on a NetWare server (supported 
only on NetWare 5.x and later). It routes all IP packets to IPX and vice versa. 


The RConsoleJ Proxy Agent advertises its services using Service Location Protocol (SLP). 





IMPORTANT: If the target NetWare server uses only IPX, the NetWare server (loaded with the 
RConsoleJ Proxy Agent) must have both IP and IPX stacks installed. 


Overview 
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What's New 


This section includes the features that were updated in the Remote Server Management for 
NetWare® since its release in NetWare 6.0: 


+ You can send lengthy console commands to the server using the new Buffer Input utility. You 
can also send commands in the server's native language using Buffer Input. 
See “Sending Console Commands in the Server's Native Language” on page 25. 

¢ It supports SSL-based secure session using the Secure IP connection option. 
See “Initiating a Secured IP Connection” on page 20. 


For more information on SSL, see the SSL documentation (http://home.netscape.com/eng/ss13/ 
draft302.txt). 


+ It supports an Unsecure IP connection for backward compatibility with NetWare 5 and 
NetWare 6. 


See “Initiating an Unsecure IP Connection” on page 21. 
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Migrating RConsoleJ from 
NetWare 6.5 to OES 2 Linux 


This section contains the following information: 


+ Section 3.1, “Coexistence,” on page 13 


¢ Section 3.2, “Migration,” on page 13 


3.1 Coexistence 


This section provides information regarding the compatibilitv and coexistence of RConsolej utilitv 
with existing networks containing NetWare® or Linux platforms. 


3.1.1 Compatibilitv 


The following table summarizes the compatibilitv of RConsolej utilitv with various operating 
svstems: 


Table 3-1 Compatibility Matrix for RConsoleJ on NetWare and SUSE Linux Operating Systems 


Operating System Compatible Versions 





NetWare NetWare 6.5 SP3 or later 
NetWare 6.x 
NetWare 5.x 

Linux Not available 


3.1.2 Coexistence Issues 


When using older versions (any versions before NetWare 6.5 SP3) of the RConsoleJ client 
(rconj.exe) to securely connect with a server running the NetWare 6.5 SP3 or later versions of 
rconag6.nlm, you might experience difficulty connecting to the target server if you do not accept 
the server certificate on the first connection attempt. 


To work around this issue: 


1 From the System Console of the target server, unload and reload the rconag6.nlm. 


2 Retry the connection and accept the certificate. 


3.2 Migration 


RConsoleJ is not available on OES 2 Linux. Other utilities are available for accessing the Linux 
console remotely. 


Migrating RConsoleJ from NetWare 6.5 to OES 2 Linux 
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Running RConsoleJ ina 
Virtualized Environment 


RConsoleJ runs in a virtualized environment just as it does on a physical NetWare® server and 
requires no special configuration or other changes. 


To get started with virtualization, see “Introduction to Xen Virtualization” (http://www.novell.com/ 
documentation/sles10/book_virtualization_xen/data/sec_xen_basics.html) in the Virtualization with 
Xen (http://www.novell.com/documentation/sles10/book virtualization xen/data/ 

book virtualization xen.html) guide. 


For information on setting up virtualized NetWare, see “Installing and Managing NetWare on a Xen- 
based VM” in the OES 2 SP2: Installation Guide. 
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Setting Up RConsoleJ 


This section contains the following sections: 


¢ Section 5.1, “Loading Agents at Startup,” on page 17 

¢ Section 5.2, “Loading the RConsoleJ Agent,” on page 18 

+ Section 5.3, “Running the RConsoleJ Client,” on page 19 

+ Section 5.4, “Loading the RConsoleJ Proxy Agent on a Proxy Server,” on page 19 


¢ Section 5.5, “Initiating Remote Sessions Using RConsoleJ,” on page 20 


5.1 Loading Agents at Startup 


You can load either the RConsoleJ Agent or the RConsoleJ Proxy Agent when you start the server. 


+ Section 5.1.1, “Loading the RConsoleJ Agent at Startup,” on page 17 
+ Section 5.1.2, “Loading the RConsoleJ Proxy Agent at Startup,” on page 18 


5.1.1 Loading the RConsoleJ Agent at Startup 


You can load RConsoleJ Agent (rconag6.n1m) at startup using either of the following methods. 
+ “Using Encrypted Password (Recommended)” on page 17 
+ “Using Plain Text Password” on page 17 

Using Encrypted Password (Recommended) 


1 Create or change the ldrconag.ncf script file. 
1a At the System Console prompt, enter rconag6 encrypt. 


1b On the RConsoleJ Agent server screen, enter the password and port numbers when 
prompted. 


1c When prompted to save the displayed command to the sys:system/ldrconag.ncf file, 
type y and then press any key. 


2 Prepare the autoexec.ncf file to run the ldrconag.ncf script file at startup. 


2a Comment out the following line: 

load rconag6 user defined password here 2034 16800 2036 
2b Add the following line: 

ldrconag 


Using Plain Text Password 


Add the following line to the autoexec.ncf file: 
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load rconag6 user defined password 2034 16800 2036 


5.1.2 Loading the RConsoleJ Proxy Agent at Startup 


To load the RConsoleJ Proxy Agent (rconprxy.nlm) at the startup, specify the following line in the 
autoexec.ncf file: 


load rconprxy 2035 


5.2 Loading the RConsoleJ Agent 


If you didn't load the RconsoleJ Agent when you started the server, you can use this procedure to do 
it. 


1 At the System Console prompt, enter 
RCONAG6 


2 Enter the password you want network administrators to use when accessing the target 
NetWare” server using RConsoleJ. 


3 Enter the TCP port number. 
The default value is 2034. 
If the server communicates using IPX™ only, enter -1 to disable TCP listening. 
To enable listening over a dynamically assigned port, enter 0. 

4 Enter the SPX™ port number on which RCONAG6 will listen for a proxy server. 
The default is 16800. 
If the server communicates using IP only, enter -1 to disable SPX listening. 


To enable listening over a dynamically assigned port, enter 0. 





NOTE: /DEV/TCP and /DEV/TCPSSL will fail if you are using a pure IPX server. 





To enable RconsoleJ across the firewall, keep the following ports open: 2034, 2035, and 2036. 
5 Enter the TCP port number for the secure session. 

The default is 2036. 

Ensure that the Key Material Object named SSL CertificateDNS has been created. 





NOTE: The Secure connection is available only on IP and not on IPX. 
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5.3 Running the RConsoleJ Client 


You can run the RConsoleJ from a workstation or from a NetWare server to connect to and manage 
a different server. 


+ Section 5.3.1, “Running the RConsoleJ Client from a Workstation,” on page 19 
¢ Section 5.3.2, “Running the RConsoleJ Client on a NetWare Server,” on page 19 


5.3.1 Running the RConsoleJ Client from a Workstation 


You can run the RConsoleJ Client on a workstation using either of the following methods: 


+ From a Windows* 2000/XP workstation, ensure that you have a drive mapped to the root of 
volume sys: on the NetWare server. From the Windows desktop, browse to 
ConsoleOne_installation_directory\1.2 and run rconj.exe. 


* In ConsoleOne®, right-click the NetWare Server object that you want to remotely control and 
click Remote Console, or click the NetWare Server object and then select Remote Console from 
the Tools menu. 


5.3.2 Running the RConsoleJ Client on a NetWare Server 


You can run the RConsoleJ Client on a NetWare server using any of the following methods: 


+ In ConsoleOne, right-click the NetWare Server object that you want to remotely control and 
click Remote Console, or click the NetWare Server object and then from the Tools option click 
Remote Console. 


+ At the System Console prompt, enter rconj.ncf. 
+ At the server GUI, click Novell > Programs > RConsoleJ. 


5.4 Loading the RConsoleJ Proxy Agent on a 
Proxy Server 


When the NetWare server is running the RConsoleJ Proxy Agent, the RConsoleJ Client can 
communicate through it with the target NetWare server that uses only IPX to communicate. 


If you didn't load the RconsoleJ Proxy Agent when you started the server, you can use this procedure 
to load it. 


1 Make sure an IP/IPX stack is loaded. 


2 Atthe System Console prompt, enter the following command: 


rconprxy 


3 Enter the TCP port number where RCONPRXY will listen for RConsolej. 
The default is 2035. 


To enable listening over a dynamically assigned port, enter 0. 
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5.5 Initiating Remote Sessions Using RConsoleJ 


The information in this section can help vou initiate remote sessions using RConsolej in the 
following scenarios: 


¢ Section 5.5.1, “Scenario 1: An IP Client Controlling an IP or IP/IPX NetWare Server,” on 
page 20 


+ Section 5.5.2, “Scenario 2: An IP Client Controlling an IPX NetWare Server,” on page 22 


5.5.1 Scenario 1: An IP Client Controlling an IP or IP/IPX 
NetWare Server 


+ “Prerequisites” on page 20 

+ “Initiating a Secured IP Connection” on page 20 

+ “Initiating an Unsecure IP Connection” on page 21 
Prerequisites 


U “Loading the RConsoleJ Agent” on page 18 





U “Running the RConsoleJ Client” on page 19 


Initiating a Secured IP Connection 


The RConsoleJ Client communicates directly with the RConsoleJ Agent using TCP/IP. 
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Figure 5-1 RConsoleJ Client Communicating with the Target NetWare Server over Secure IP 
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1 Inthe RConsoleJ Connection dialog box, select Secure IP. 


2 Specify the IP address of the target NetWare server, or click the Remote Servers icon, then 
select the target NetWare server from the list. 


3 Specify the password provided during loading of the RConsoleJ Agent on the target server. 
4 Specify the port number. 

The default is 2036. 
5 Click Connect. 


6 To ensure server authentication, read the Untrusted Certificate Verification server certificate 
issued by the target server and click OK to accept it. 


Initiating an Unsecure IP Connection 


The RConsoleJ Client communicates directly with the RConsoleJ Agent using TCP/IP. 
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Figure 5-2 RConsoleJ Communicating with the Target NetWare Server over Unsecure IP 
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1 Inthe RConsoleJ Connection dialog box, select Unsecure IP. 
2 Select Connect Directly as the unsecure connection option. 


3 Specify the IP address of the target NetWare server, or click the Remote Servers icon and then 
select the target NetWare server from the list. 


4 Specify the password provided during loading the RConsoleJ Agent. 
5 Specify the port number. 

The default is 2034. 
6 Click Connect. 


5.5.2 Scenario 2: An IP Client Controlling an IPX NetWare 
Server 


+ “Prerequisites” on page 22 


+ ''Tnitiating an IPX Connection” on page 23 


Prerequisites 


U “Loading the RConsoleJ Agent” on page 18 
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Q “Running the RConsoleJ Client” on page 19 





Q “Loading the RConsoleJ Proxy Agent on a Proxy Server” on page 19 


Initiating an IPX Connection 


The RConsoleJ Client communicates with the RConsoleJ Agent through RConsoleJ Proxy Agent 
because the target NetWare server is based purely on IPX. 


The RConsoleJ Proxy Agent is loaded on a NetWare server (proxy server) that has both IP and IPX 
stacks loaded. The RConsoleJ Proxy Agent receives all the IP requests from the RConsoleJ Client, 
converts them to IPX requests, and then sends them to the RConsoleJ Agent and vice-versa. 


Figure 5-3 RConsoleJ Client Communicating with the Target NetWare Server through the Proxy Server 
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*|f the target server uses IPX, the proxy server must have 
both IP and IPX stacks loaded. 


In the RConsoleJ Connection dialog box, select Unsecure IP. 
Select Connect Via Proxy as the unsecure connection option. 
From the Connect Type drop-down list, select Connect through Proxy. 


Type the IP/IPX address of the target NetWare server, or select SPX to get the IPX address and 
TCP to get the IP address. 


5 Make sure the appropriate default port is selected after specifying the IPX or IP address. 
The default is 16800 for IPX and 2034 for IP. 


R OD = 
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6 Specifv the IP address of the proxv server, or click the Remote Servers icon and then select a 
proxv server from the list. 


7 Type the port number that was specified during the loading of the RConsoleJ Proxy Agent. 
The RConsoleJ Client communicates with the RConsoleJ Proxy Agent on this port. 
The default is 2035. 

8 Click Connect. 
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Managing NetWare Servers 
Remotelv 


After RConsoleJ establishes connections with the NetWare® server, you can view and manage the 
target NetWare server from your desktop or remote server. 


The following sections explain the tasks you can perform to effectively manage a remote NetWare 
Server. 


¢ Section 6.1, “Sending Console Commands in the Server's Native Language,” on page 25 
¢ Section 6.2, “Synchronizing RConsoleJ Client and Target NetWare Screens,” on page 26 
¢ Section 6.3, “Changing the Password of the RConsoleJ Agent,” on page 26 


6.1 Sending Console Commands in the Server's 
Native Language 


You can send console commands in the server's native language from the RConsoleJ Client using 
Buffer Input as shown in the following graphic. The buffer stores a list of ten history commands. 


Figure 6-1 Send Console Commands in Japanese Using Buffer Input 
Ba Novell oleJ: JAP-185 BEE 


an en dea ml m | | Bl 


VĊINIŻ rH avy 


' NetWare Text Edito 

N'-3°3%, 4.15 2800 -2- 2 

Gopyright 1989-1998 Novell, Inc. All rights reserved. 
AP-185: 


Buffer Input edit 7" YTA Pa 78 © © CYC AG Bra ZY | Send | 





To send console commands: 


1 From the Novell® RConsoleJ Client window, enter the command that you want to run at the 
target server in the Buffer Input field. 


2 Click Send. 


Managing NetWare Servers Remotely 


25 


6.2 Synchronizing RConsoleJ Client and Target 
NetWare Screens 


You can synchronize the screen displayed on the target NetWare server and the screen displayed on 
the RConsoleJ Client with each other. Switching the screen in the RConsoleJ Client switches the 
screen at the target server console and vice versa. 


To synchronize the screens, from the Novell RConsoleJ window, click Sync. 


To switch the screen on the server console to the currently activated screen on the RConsoleJ Client, 
click Activate. 


6.3 Changing the Password of the RConsoleJ 
Agent 


You can change the agent password to ensure that RConsoleJ sessions are secure. 


To change the agent password for a remotely managed NetWare server, do the following at the 

System Console prompt: 

Enter unload rconag6. 

Enter rconag6 encrypt. 

Enter a new password. 

Enter the TCP port number. 

The default is 2034. 

5 Enter the SPX™ port number. 
The default is 16800. 

6 Enter the TCP port number for the secure session. 
The default is 2036. 


7 When prompted to write the displayed load command to the ldrconag.ncf file, type y and 
then press any key. 


R WD = 


If you type y, the ldrconag.ncf file is updated and the new password is in effect when the 
agent is loaded from the command in the 1drconag.ncf script file after you reboot the server. 


If you type n, the ldrconag.ncf file is not updated. The new password is valid only for the 
current session. At a later time, if you load RCONAG6 from the ldrconag.ncf file, the 
previously saved password is used. 
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Securitv Considerations for 
RConsoleJ 


No specific issues have been identified specificallv for RConsolej. 


For overall security considerations, see “Security” in the NW 6.5 SP8: Planning and Implementation 
Guide. 
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Documentation Updates 


To help you keep current on updates to the documentation, this section contains information on 
content changes that have been made in this Remote Server Management Administration Guide 
since the initial release of NetWare® 6.5. 


The documentation was updated on the following dates: 


+ Section A.1, “November 9, 2009,” on page 29 
e Section A.2, “November 1, 2005 (NetWare 6.5 SP5),” on page 29 
+ Section A.3, “February 28, 2005 (NetWare 6.5 SP3),” on page 29 


A.1 November 9, 2009 


This guide has been modified for publication on the NetWare 6.5 SP8 Documentation Web site. 


A.2 November 1, 2005 (NetWare 6.5 SP5) 


Updates were made to this guide. 


A.2.1 Entire Guide 


Location Change 
Entire guide. Page design reformatted to comply with revised Novell® documentation 
standards. 


A.3 February 28, 2005 (NetWare 6.5 SP3) 


Updates were made to the following sections: 


* Section A.3.1, “Coexistence and Migration,” on page 29 

+ Section A.3.2, “Managing NetWare Servers Remotely,” on page 30 
+ Section A.3.3, “Setting Up RConsolej,” on page 30 

+ Section A.3.4, “Entire Guide,” on page 30 


A.3.1 Coexistence and Migration 


Location Change 

“Migrating RConsoleJ from Added coexistence and migration information for the OES 2 release. 
NetWare 6.5 to OES 2 Linux” 

on page 13 
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A.3.2 Managing NetWare Servers Remotelv 


Location Change 


Changing the Password ofthe Added these procedures. 
RConsoleJ Agent (page 26) 


A.3.3 Setting Up RConsoleJ 


Location Change 


“Setting Up RConsoleJ” on Changed the flow of the entire section, updated Loading the RConsoleJ 

page 17 Agent procedures, updated instructions for starting an IPX™ section in 
Scenario 2, and renamed the “Deploying RConsoleJ” section to 
“Initiating Remote Sessions Using RConsoleJ.” 


A.3.4 Entire Guide 


Location Change 


Entire guide. Changed document title to distinguish the utility for running on NetWare 
only, updated the “About This Guide” and “Overview” information to 
match current style guidelines, and added introductory paragraphs to 
several sections. 
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